CVE-2022-24439
CRITICAL 9.8EPSS 5.4%
All versions of package gitpython are vulnerable to Remote Code Execution (RCE) due to improper user input validation, which makes it possible to inject a maliciously crafted remote URL into the clone command. Exploiting this vulnerability is possible because the library makes external calls to git without sufficient sanitization of input arguments.
- CVSS v4.0
- 9.2 CRITICAL
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N - CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 8.1 HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 8.1 HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS
- 5.38% chance of exploitation in the next 30 days, 92th percentile
- Published
- 2022-12-12
- Updated
- 2025-11-03
Proof-of-concept exploits (3)
- https://security.snyk.io/vuln/SNYK-PYTHON-GITPYTHON-3113858
- Makkkiiii/GitPython-Exploit-CVE-2022-244391★ · 2025-07-12
- muhammadhendro/CVE-2022-244390★ · 2024-10-16